Research
Security News
Malicious PyPI Package ‘pycord-self’ Targets Discord Developers with Token Theft and Backdoor Exploit
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
umd-free-zone
Advanced tools
Creates a define and exports free zone for your UMD scripts to safely register globally
umd-free-zone is meant to prevent your UMD-compatible scripts from falling for unwanted global AMD and CommonJS shims.
Just add umd-free-zone/start.js before your scripts and umd-free-zone/end.js after them.
This will ensure your scripts register globally.
Imagine you want to load the UMD compatible React from unpkg
and intend for it to become a global (window.React
).
Yet, you have an evil Mailchimp script that brutally exports a global define
function, and you can't guarantee your React will load before the nasty AMD leak.
umd-free-zone
to the rescue! Just add it before and after the scripts you want to become global.
React will fall for the alien global define
.
// Nasty script that globally defines a `define` function
<script src="https://downloads.mailchimp.com/js/signup-forms/popup/embed.js"></script>
<script src="https://unpkg.com/react@16.1.1/umd/react.production.min.js"></script>
<script> window.React // undefined! Ouch. </script>
Wrap your scripts in umd-free-zone
start and end:
// Nasty script that globally defines a `define` function
<script src="https://downloads.mailchimp.com/js/signup-forms/popup/embed.js"></script>
<script src="https://unpkg.com/umd-free-zone@0.1.3/start.js"></script>
<script src="https://unpkg.com/react@16.1.1/umd/react.production.min.js"></script>
<script> window.React // undefined! Ouch. </script>
<script src="https://unpkg.com/umd-free-zone@0.1.3/end.js"></script>
// The leaky AMD works as usual from here onwards, if you want it to.
FAQs
Creates a define and exports free zone for your UMD scripts to safely register globally
We found that umd-free-zone demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
Security News
The UK is proposing a bold ban on ransomware payments by public entities to disrupt cybercrime, protect critical services, and lead global cybersecurity efforts.
Security News
Snyk's use of malicious npm packages for research raises ethical concerns, highlighting risks in public deployment, data exfiltration, and unauthorized testing.